CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-34727

CVSS 9.8v3.1pub. 2021-09-23upd. 2024-11-21

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attacker to cause a buffer overflow and possibly execute arbitrary commands with root-level privileges, or cause the device to reload, which could result in a denial of service condition.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cisco 1000 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4g\/6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 2p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1120 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1160 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4000 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4221 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 422 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4321 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4331 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4351 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4431 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4451 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4451 X Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 4461 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco Asr 1000

    HW
    Cisco
    all versions
  • Cisco Asr 1000 Esp100

    HW
    Cisco
    all versions
  • Cisco Asr 1000 Series

    HW
    Cisco
    all versions
  • Cisco Asr 1000 Series Route Processor \(rp2\)

    HW
    Cisco
    all versions
  • Cisco Asr 1000 Series Route Processor \(rp3\)

    HW
    Cisco
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoSMemory
CWE
References

Related vulnerabilities

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2021-1300CRITICAL9.8PL ✓same product

Krytyczne podatności buffer overflow w Cisco SD-WAN umożliwiające RCE

CVE-2021-1301CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu w Cisco SD-WAN — krytyczne podatności

CVE-2020-3375CRITICAL9.8PL ✓same product

Buffer overflow w Cisco SD-WAN — zdalne wykonanie kodu jako root

CVE-2019-12643CRITICAL10.0PL ✓same product

Cisco IOS XE REST API — pominięcie uwierzytelnienia w kontenerze wirtualnym